आरंभ Legal Documents

Responsible Disclosure

We take security seriously and welcome researchers who help us keep our customers safe.

Last updated: August 2026Effective: 1 September 2026
§1

Overview

आरंभ Tours & Travels is committed to maintaining the security of our platform and protecting our customers' data. Security researchers play a vital role in identifying vulnerabilities we may have missed.

If you have discovered a security vulnerability in any आरंभ system, we encourage you to disclose it to us responsibly before making it public. We are grateful for responsible security research.

This policy is our public commitment to how we will treat security researchers who report vulnerabilities to us in good faith.
§2

How to Report a Vulnerability

Please submit your vulnerability report via email:

Email
security@aarambhatravels.in
Subject line
Use: "Security Vulnerability Report – [Brief Description]"
Encryption
PGP encryption not currently required, but strongly encouraged for sensitive reports.

Please include in your report:

  • Description of the vulnerability and its potential impact
  • Step-by-step reproduction steps (proof-of-concept code or screenshots)
  • Affected URL(s), parameters, or API endpoint(s)
  • Your name/handle and contact email for follow-up (optional but appreciated)
Do not access, download, modify, or delete customer data to prove the vulnerability. A minimal proof-of-concept is sufficient.
§3

In Scope

The following आरंभ properties are in scope for responsible disclosure:

  • aarambhatravels.in — Main customer website
  • admin.aarambhatravels.in — CRM admin portal
  • api.aarambhatravels.in — Backend REST API

Priority issues we want to hear about:

  • Authentication bypass or privilege escalation
  • Insecure Direct Object Reference (IDOR) allowing access to other users' data
  • SQL injection or NoSQL injection
  • Cross-Site Scripting (XSS) with meaningful impact
  • Cross-Site Request Forgery (CSRF)
  • Sensitive data exposure (API keys, customer PII)
  • Payment flow vulnerabilities
  • Server-Side Request Forgery (SSRF)
§4

Out of Scope

The following are generally not eligible for our disclosure programme:

  • Volumetric Denial of Service (DoS/DDoS) attacks
  • Social engineering attacks against our staff
  • Physical security attacks
  • Vulnerabilities in third-party software we use (report directly to that vendor)
  • Self-XSS that requires the victim to take deliberate unusual action
  • Missing security headers without a demonstrated exploit
  • SSL/TLS version or cipher suite issues without proven attack
  • Username/email enumeration via timing (we have fixed this; please verify first)
  • Clickjacking on pages with no sensitive actions
§5

Our Response Commitment

Acknowledgement
We will acknowledge your report within 72 hours of receipt.
Triage
We will assess severity and impact within 7 business days and communicate our findings.
Resolution
We target fixing critical vulnerabilities within 14 days and high-severity within 30 days.
Notification
We will notify you when the vulnerability is patched.
Credit
With your permission, we are happy to credit you in our security changelog.
Bounties
We currently do not offer monetary bug bounties, but we appreciate and acknowledge all valid reports.
Please give us adequate time to address the issue before any public disclosure. We ask for a minimum of 90 days from our acknowledgement before publishing your findings.
§6

Safe Harbor

We consider security research and disclosure conducted in accordance with this policy to be authorised activity. आरंभ Tours & Travels will not initiate or recommend legal action against researchers who:

  • Report vulnerabilities to us before public disclosure
  • Act in good faith and avoid violating privacy, causing service disruption, or destroying data
  • Do not access or download more data than is strictly necessary to demonstrate the vulnerability
  • Stop testing immediately upon discovering customer personal data and report it to us
This safe harbor applies only to activities covered by this policy. Any actions beyond these bounds — including unauthorized access, data exfiltration, or testing production systems in a disruptive manner — are not covered.

If you have any questions about whether your planned research is in scope, email security@aarambhatravels.in before proceeding.